NetApp ONTAP CIFS/SMB Shares and Permissions - 夜莺博客

NetApp ONTAP CIFS/SMB Shares and Permissions

ONTAP SMB problems are almost never about SMB itself. They come from a mismatch between three separate permission layers: the share ACL that ONTAP enforces, the NTFS or UNIX file permissions on the volume, and the SVM's name services. Creating a share is three commands; making it actually work for a user requires understanding all three layers. This guide covers the ONTAP side end to end, including the access checks that prove a user will really be able to open the file.

Prerequisites: SVM, LIF and DNS

The CIFS server name must resolve in DNS to a data LIF on the same SVM. If the SMB clients cannot resolve the server name, no amount of share configuration helps.

vserver services name-service dns show
network interface show -vserver svm1
vserver cifs show -vserver svm1
vserver cifs domain discovered-servers show -vserver svm1

Create the CIFS Server

vserver cifs create -vserver svm1 -cifs-server SMB1   -domain corp.example.com -ou "OU=Storage,DC=corp,DC=example,DC=com"

vserver cifs show
vserver cifs session show -vserver svm1

The ONTAP machine account is created in the specified OU. Verify that the account has the right to create its own SPNs, or pre-stage the account in Active Directory before running the command.

Create the Volume and Share

volume create -vserver svm1 -volume data1 -aggregate aggr1 -size 500g   -junction-path /data1 -security-style ntfs -type RW

vserver cifs share create -vserver svm1 -share-name data1   -path /data1 -comment "Department data" -share-properties oplocks,browsable,changenotify

Note -security-style ntfs at volume creation time. Changing security style later is possible but is a source of subtle permission surprises; decide up front. Keep the share name and the volume name aligned so that admins do not have to remember two mappings.

Share-Level ACLs

By default a new share grants Full Control to Everyone and relies on NTFS permissions. That is the Microsoft recommendation, but many compliance frameworks require a restrictive share ACL as well. Set it explicitly:

vserver cifs share access-control create -vserver svm1 -share data1   -user-or-group "CORP\Domain Admins" -permission Full_Control -user-group-type windows

vserver cifs share access-control create -vserver svm1 -share data1   -user-or-group "CORP\Storage Users" -permission Change -user-group-type windows

vserver cifs share access-control show -vserver svm1 -share data1

Share permissions and NTFS permissions are intersected - the most restrictive of the two applies. Removing Everyone and granting Change to a group means those users are then limited by NTFS on the files themselves.

NTFS Permissions from the ONTAP CLI

vserver security file-directory show -vserver svm1 -path /data1
vserver security file-directory ntfs create -vserver svm1 -ntfs-sd sd1   -owner CORP\Domain Admins -group "CORP\Domain Users" -access-control "0:0x001f01ff:0x0"
vserver security file-directory policy create -vserver svm1 -policy pol1
vserver security file-directory policy task add -vserver svm1 -policy pol1   -path /data1 -security-type ntfs -ntfs-mode propagate -ntfs-sd sd1
vserver security file-directory policy task apply -vserver svm1 -policy pol1

Validating Access Before Users Complain

ONTAP can evaluate a user's effective access path by path - far faster than opening tickets with the storage team.

vserver security file-directory show -vserver svm1 -path /data1/reports
vserver cifs share show -vserver svm1
vserver cifs session show -vserver svm1 -instance
vserver cifs domain user show -vserver svm1 -user CORP\jdoe

Walk the path one directory at a time when troubleshooting: a blocked share ACL stops access at the root, while a missing traverse permission on an intermediate folder produces the misleading "access denied" on a file the user can otherwise read. For the network plumbing underneath, see ONTAP SVM and LIF creation, and for export policy equivalents when NFS shares the same data, ONTAP export policy configuration.

原文链接:https://docs.netapp.com/us-en/ontap-cli/vserver-cifs-share-create.html